Venafi / blueprint-securesoftwarepipelineView external linksLinks
For engineers and security teams driving fast and secure software supply chains
☆85Feb 6, 2023Updated 3 years ago
Alternatives and similar repositories for blueprint-securesoftwarepipeline
Users that are interested in blueprint-securesoftwarepipeline are comparing it to the libraries listed below
Sorting:
- Container image provenance spec that allows tracing CVEs detected in registry images back to a CVE's source of origin.☆45Oct 30, 2023Updated 2 years ago
- Example repository that demonstrates a supply chain security workflow using Syft, Grype, Cosign☆12Sep 15, 2021Updated 4 years ago
- Powershell module to fully automate your CyberArk Certificate Manager Self-Hosted and SaaS (Venafi TLS Protect Datacenter and Cloud) plat…☆42Feb 5, 2026Updated last week
- An example repo demonstrating keyless signing with Github Actions☆11May 24, 2022Updated 3 years ago
- fatt tries to find any purl in your project by looking at predefined fields in the supported packages. These fields describe using a purl…☆11Jan 26, 2026Updated 2 weeks ago
- Witness Examples☆12Feb 27, 2024Updated last year
- Kubernetes tools in a "distroless" container☆13Oct 30, 2023Updated 2 years ago
- go-ima is a tool that checks if a file has been tampered with. It is useful in ensuring integrity in CI systems☆13Sep 28, 2023Updated 2 years ago
- SLSA level 3 action☆11Apr 26, 2024Updated last year
- A kubectl plugin to run kubectl macro that wraps a set of kubectl calls into one command to be run many times.☆11Jun 28, 2021Updated 4 years ago
- ☆11Nov 11, 2022Updated 3 years ago
- Tooling and library for generation, validation and verification of supply chain metadata documents and frameworks☆33Apr 22, 2025Updated 9 months ago
- ☆13Oct 27, 2020Updated 5 years ago
- Use ORT in your GitLab pipelines☆15Nov 11, 2025Updated 3 months ago
- Demos and resources of the Istio + Gatekeeper talks at IstioCon 2022 and GitOpsCon 2022☆14Sep 4, 2023Updated 2 years ago
- AWS Cloud Quest: Cloud Practitioner☆24Apr 8, 2022Updated 3 years ago
- To manage Docker Content Trust and Notary certificates☆13Updated this week
- Comparison of Chainguard Images to others☆21Updated this week
- Overview of philips-labs helm charts☆17Jan 27, 2026Updated 2 weeks ago
- Sample application showcasing the use of Dapr to build microservices based apps☆15Feb 4, 2026Updated last week
- Go client SDK and command line utility designed to simplify integrations by automating key generation and certificate enrollment using Ve…☆103Updated this week
- AWS managed IAM policies☆16Mar 24, 2022Updated 3 years ago
- ☆16May 15, 2024Updated last year
- Deprecated, see VenafiPS project. PowerShell module to access the features of Venafi Trust Protection Platform REST API☆18Nov 29, 2021Updated 4 years ago
- ☆18Apr 29, 2024Updated last year
- Prototype in-toto attestation verifier based on ITE-10 and ITE-11 layouts☆18Feb 6, 2026Updated last week
- Friends of in-toto! A place to record integrations and adoptions of the in-toto specification.☆20Updated this week
- Simplify Kubernetes Secrets Management with Dockhand Secrets Operator☆18Nov 24, 2025Updated 2 months ago
- Various tools, images, etc. to support the Wolfi OSS project☆27Updated this week
- A curated list of awesome CNAB (Cloud Native Applications Bundles) | https://cnab.io/☆16Dec 17, 2020Updated 5 years ago
- Lambda function for verifying signed images in ECS☆36Mar 9, 2024Updated last year
- ☆255Updated this week
- Stuff to make standing up sigstore (esp. for testing) easier for e2e/integration testing.☆71Feb 6, 2026Updated last week
- How small can a Java application container image be☆21Feb 17, 2023Updated 2 years ago
- GitHub actions for the chainguard-images☆21Updated this week
- Go implementation of witness☆44Updated this week
- A specification for signing methods and formats used by Secure Systems Lab projects.☆94Nov 10, 2025Updated 3 months ago
- ☆23Oct 26, 2021Updated 4 years ago
- 🔮 ✈️ to integrate OPA Gatekeeper's new ExternalData feature with cosign to determine whether the images are valid by verifying their sig…☆79Dec 4, 2025Updated 2 months ago